# facebook-clone-rho-six.vercel.app — MALICIOUS > Domain facebook-clone-rho-six.vercel.app impersonates Facebook to steal credentials. VirusTotal flags 24/95 vendors. Verify on PhishDestroy before clicking. ## Summary PhishDestroy identifies an active phishing campaign targeting Facebook users through the domain facebook-clone-rho-six.vercel.app. This domain is a fraudulent clone designed to mimic Facebook’s login interface, tricking users into entering their credentials into a malicious form. The threat is classified as brand impersonation with a high risk level, indicating active exploitation by threat actors to harvest login details for account takeovers, financial fraud, or further social engineering attacks. Users interacting with this domain risk exposing their Facebook credentials, which could lead to unauthorized access, data theft, or propagation of malware to connected accounts. This domain was flagged by 24 out of 95 security vendors on VirusTotal, demonstrating widespread detection of its malicious nature. It is registered through Vercel Inc., a legitimate hosting provider, which has been exploited to host this phishing content. The domain resolves to IP address 216.198.79.3 and is secured with a Google Trust Services SSL certificate, adding a false sense of legitimacy. Additionally, it appears on 1 security blocklist and is flagged by Google Safe Browsing under the category SOCIAL_ENGINEERING, confirming its malicious intent. These technical indicators highlight the domain’s role in a coordinated phishing operation aimed at deceiving users. If you have visited facebook-clone-rho-six.vercel.app, immediately change your Facebook password and enable two-factor authentication. Scan your device for malware using reputable antivirus software, as threat actors may have deployed additional payloads. Avoid entering any credentials on this domain and report the site to PhishDestroy for further investigation. Always verify URLs and use official Facebook domains (facebook.com or its regional equivalents) for secure logins. Stay vigilant for unsolicited messages or links, even if they appear to originate from trusted contacts. ## Threat Details - Verdict: MALICIOUS - Site status: unknown (HTTP ?) - Target brand: Facebook ## Domain Intelligence - Registrar: Vercel Inc. - IP: 216.198.79.3 ## Detection Status - VirusTotal: 24 vendors flagged - Google Safe Browsing: FLAGGED - Blocklists: 1 hits Lists: ["Phishunt"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/c9d3a031-80d0-4c13-9690-6e2272a30676 - PhishDestroy: https://phishdestroy.io/domain/facebook-clone-rho-six.vercel.app/ - LLM endpoint: https://phishdestroy.io/domain/facebook-clone-rho-six.vercel.app/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/facebook-clone-rho-six.vercel.app/ Last updated: 2026-04-15